Tag: ai
-
Perplexity Builds Guardrails to Rein in Rogue AI Agents
Open-Source Numbat Blocks Agent Actions That Violate Enterprise Security Policies. Perplexity designed its open-source tool Numbat tool to detect and block AI agents from stepping outside enterprise safety policies. The tool sits between when the agent starts to think about doing something and when it takes action, so it will stop agents from going rogue.…
-
When AI Risk Becomes a Board Liability
CIOs Can Strengthen Oversight Through Reporting, Records and Insurance Reviews. AI failures can trigger financial, regulatory and reputational exposure that reaches the boardroom. Reed Smith partners Carolyn Rosenberg and Andy Moss explain how CIOs can document oversight, validate corporate claims and test insurance for coverage gaps. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/when-ai-risk-becomes-board-liability-a-32594
-
FDA Weighing Possible Regs for GenAI Medical Devices
Agency Seeks Public Input on Risk-Based Oversight Approach Across Product Life Cycle. The U.S. Food and Drug Administration is seeking public feedback on the varying risks and other considerations involving generative artificial intelligence-enabled medical devices to inform the agency as it contemplates how to advance a regulatory approach for these evolving products. First seen on…
-
‘CoSnitch’ Attack Tricked Copilot into Mapping Out Architecture
Researchers discovered a meta-hacking technique that can manipulate the AI service into revealing its own security weaknesses. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/cosnitch-attack-copilot-mapping-out-architecture
-
Every Company Now Needs An AI Risk Officer: Accenture Expert
For most companies, it has now become essential to clearly designate a single executive responsible for ensuring that the drive to deploy AI does not outpace cybersecurity and safety, according to Accenture cyber intelligence leader Ryan Whelan. First seen on crn.com Jump to article: www.crn.com/news/security/2026/every-company-now-needs-an-ai-risk-officer-accenture-expert
-
Fortinet Buys Virtue AI for Agent and Model Runtime Controls
Acquisition Adds Offensive and Defensive Testing for Agents and Models. Fortinet acquired Virtue AI’s technology to extend FortiAIGate with red- and blue-team testing, runtime controls and policy enforcement for AI agents, models, skills and MCP services as enterprises deploy more autonomous workflows. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/fortinet-buys-virtue-ai-for-agent-model-runtime-controls-a-32592
-
Project noRecognition: Teaching AI to Fool Surveillance Cameras
Researchers tested 31 million patterns to disrupt surveillance AI, with promising results but significant gaps between simulation and real-world use. The Kansas City-based cybersecurity researcher Bill Swearingen spent the past year doing something that sounds almost too simple to work: printing patterns, watching cameras fail to detect them, and repeating. TechCrunch reports that after roughly…
-
OpenAI Overhauls Safety Protocols After Its AI Agents Went Rogue
The ChatGPT maker says its upcoming Astra model may have reached “critical” cyber capabilities, prompting it to halt a significant number of training runs while it tightens internal safeguards. First seen on wired.com Jump to article: www.wired.com/story/openai-overhauls-safety-protocols-after-its-ai-agents-went-rogue/
-
Hugging Face Breach Raises Big Questions About AI Security Controls
Adam Shostack, president of Shostack & Associates and an affiliate professor at the University of Washington, talks with the Dark Reading News Desk about why he was blown away by OpenAI’s revelations regarding the Hugging Face attack. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/adam-shostack-talks-hugging-face-phantom-b
-
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Tags: ai, automation, cloud, credentials, exploit, flaw, intelligence, malicious, open-source, software, technology, vulnerabilityTwo critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts.According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows – First seen on thehackernews.com Jump…
-
Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed
The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/wiz-ai-agent-finds-snowflake/
-
Courts Face New Threat as Litigant Uses Hidden AI Prompt Injection in Filings
In what is believed to be the first decision of its kind in the U.S., a Connecticut state court judge has sanctioned a self-represented litigant for attempting to covertly influence artificial intelligence (AI) systems through hidden text embedded in court documents. In an Aug. 6 ruling in Elliott v. New York Bariatric Group, Superior Court..…
-
How to write an AI usage policy
Write an AI usage policy with this 7-step guide and free template. 63% of breached organizations lacked an AI governance policy, per IBM 2025. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/how-to-write-an-ai-usage-policy/
-
Ist die Forschung durch KI am Ende? ExChef Eric Schmidt klärt auf
First seen on t3n.de Jump to article: t3n.de/news/ki-forschung-alphafold-eric-schmidt-wissenschaft-zukunft-1757410/
-
The Governance Gaps Holding Back Enterprise Agentic Networks
Enterprise AI is moving from individual assistants to interconnected networks of autonomous agents. That creates a new governance challenge: knowing which agent acted, why it acted, what permissions it had and who authorized it. Identity, runtime policy, delegation controls and auditability are quickly becoming foundational AI security requirements. First seen on securityboulevard.com Jump to article:…
-
Taiwan Reports AI-Agent Cyberattacks on Government Networks
Taiwan says AI agents helped target government systems, highlighting how autonomous tools could accelerate cyberattacks and challenge defenders. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-ai-assisted-government-cyberattacks-apac-taiwan/
-
Cybercriminals Turn to Indirect Prompt Injection Attacks
Cybercriminals are developing indirect prompt injection tools to target AI agents. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/cybercriminals-turn-to-indirect-prompt-injection-attacks/
-
OpenAI Warns Organizations to Automate Cybersecurity as AI-Powered Attacks Accelerate
OpenAI has issued a warning that organizations need to quickly automate core cybersecurity functions as increasingly advanced AI systems make it easier and cheaper to identify, exploit, and chain security vulnerabilities. In a recent security article titled “The Defender’s Window,” OpenAI President Greg Brockman explained that the OpenAI-Hugging Face incident showcased how highly capable attackers…
-
AI “Mind Viruses” Can Spread Between Agents Through Persistent Prompt Files
Security researchers at Anthropic and Switzerland’s EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions.The work, released as a preprint on August 10, 2026, tests the technique in a simulated six-agent…
-
Meta’s legal jeopardy is growing by the day
Also: AI’s implications on cybersecurity in an era of private attacksHello, and welcome to TechScape. I’m your host, Blake Montgomery, US tech editor at the Guardian. Today in tech, we’re discussing <a href=”https://www.theguardian.com/technology/meta”>Meta’s legal danger in the US and the implications of <a href=”https://www.theguardian.com/technology/artificialintelligenceai”>artificial intelligence for cybersecurity in an era of private cyberattacks.<a href=”https://www.theguardian.com/us-news/video/2026/aug/11/why-the-us-government-is-trying-to-ban-this-chinese-dancing-robot-video-explainer”>Why the…
-
LLMs and Contextual Integrity
I have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic. “CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs”: Abstract: Large Language Models (LLMs) increasingly use persistent memory from past interactions to enhance personalization and task performance. However,…
-
AI-powered vulnerability clearinghouse faces deep skepticism, major challenges
The U.S. government’s promises about the “Gold Eagle” coordination program are overblown, experts said, but the initiative could help organizations prioritize patching and mitigation. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-vulnerability-clearinghouse-us-government-challenges/827710/
-
Google’s $10,000 refund test shows why AI agents need zero trust
Google’s open-source autonomous Customer Support Returns Agent, built using the Agent Development Kit (ADK) and Gemini, demonstrates how developers can apply zero-trust … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/18/google-zero-trust-ai-agents/
-
Proton launches free tool to show enterprises what ChatGPT and Claude know about employees
Privacy-focused tech company Proton has launched a free tool designed to show users exactly what large language models such as ChatGPT and Claude have learned about them from months or years of conversation history, a capability that speaks directly to the shadow AI problem now facing enterprise security teams. The tool, called AI Paper Trail,…
-
CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability
Tags: ai, cisa, computing, cve, cyber, cybersecurity, data, exploit, flaw, framework, infrastructure, injection, intelligence, kev, open-source, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability, tracked as CVE-2025-62593, is a code injection flaw in the Ray Project, a widely used open-source distributed computing framework often deployed for artificial intelligence workloads, machine learning development, data processing, and scalable Python…
-
AI Agents Gain Unintended Internet Access During Cybersecurity Evaluations
AI security evaluation firm has disclosed that several frontier AI models unintentionally accessed and acted against real internet-connected systems during controlled cybersecurity testing. This issue, which has since been resolved, stemmed from a single evaluation scenario in which internet access was permitted and a fictional target name overlapped with a real domain. Irregular stated that…
-
How the Mass-Adoption of AI is Redefining the Shift to Continuous Threat Exposure Management
AI adoption is expanding the enterprise attack surface faster than security teams can respond. Exposure management helps organizations discover shadow AI, protect sensitive data and prioritize exploitable risk. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/how-the-mass-adoption-of-ai-is-redefining-the-shift-to-continuous-threat-exposure-management/
-
The AI Factory’s Blind Spot Is Trust: Why Confidential AI Is the Missing Infrastructure Layer
AI factories promise scalable enterprise AI, but traditional security leaves sensitive data and model weights exposed during processing. Confidential AI closes the gap by protecting data in use with hardware isolation, encryption and cryptographic attestation. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-ai-factorys-blind-spot-is-trust-why-confidential-ai-is-the-missing-infrastructure-layer/
-
Cryptographic Attestation Is the Missing Layer for Autonomous AI Security
As autonomous AI agents gain access to sensitive systems, cryptographic attestation provides verifiable proof of identity, actions and access”, strengthening incident response, zero trust and regulatory compliance. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/cryptographic-attestation-is-the-missing-layer-for-autonomous-ai-security/

